Real-world critical vulnerability discoveries through responsible disclosure. All findings were reported ethically via authorized bug bounty programs on HackerOne.
LOCKRA discovered a critical API vulnerability on an online training academy platform that exposed the full user database without authentication.
Cleartext passwords, emails, user IDs, activation keys, and sensitive user data were publicly accessible.
This could have led to mass account takeover, credential theft, regulatory issues, and exposure of proprietary training data.
The issue was responsibly reported, triaged, and resolved. The endpoint was secured and password protection was improved.
LOCKRA found hardcoded API credentials inside a production JavaScript file for a major gaming platform.
The exposed credentials allowed administrative access to the user SSO system.
Attackers could read, modify, ban, or delete user accounts, exposing personal data, linked gaming profiles, sessions, and password reset tokens.
The vulnerability was responsibly reported and triaged as Critical with a CVSS score of 9.8.
LOCKRA identified an exposed Azure CosmosDB master key inside a production JavaScript bundle.
The master key gave full access to 9 production databases.
Sensitive partner data, sales records, HR information, financial analytics, and internal business data were at risk of being accessed, changed, or deleted.
The vulnerability was responsibly reported and triaged, with urgent recommendations to rotate keys, remove exposed credentials, and improve cloud security controls.